Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
PowerShell PSAsyncShell Reverse Shell Activity via Script Block Logging
Detects PowerShell use of PSAsyncShell by matching the tool name in logged script block text.
sigmaWindowshigh2022-10-04Windows Registry: Modify User Shell Folders Startup Values for Persistence
Alerts on Windows Registry changes to User Shell Folders startup-related values that may be used to establish persistence.
sigmaWindowshigh2022-10-01Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Flags w3wp.exe-launched commands matching China Chopper webshell execution patterns in Windows process creation logs.
sigmaWindowshigh2022-10-01Atlassian Bitbucket Command Injection Attempt via Archive API Parameters (Webserver)
Alerts on Bitbucket REST archive query parameters containing a %00--exec execution marker.
sigmahigh2022-09-29Windows IIS connection string decryption via aspnet_regiis -pdf
Flags aspnet_regiis.exe runs that target IIS connectionStrings for decryption using -pdf.
sigmaWindowshigh2022-09-28PowerShell ScriptBlock Matching Invoke-Mimikatz Credential Dump Commands (Windows)
Detects PowerShell ScriptBlocks containing Mimikatz-like credential dump and certificate extraction command strings.
sigmaWindowshigh2022-09-28AnyDesk Windows: suspicious executable/DLL writes excluding gcapi.dll
Alerts when AnyDesk.exe or AnyDeskMSI.exe writes .dll/.exe files, excluding gcapi.dll.
sigmaWindowshigh2022-09-28Windows ImagingDevices.exe Spawns Unusual Parent/Child Processes
Alerts when ImagingDevices.exe participates in atypical process parent/child chains on Windows, based on process creation telemetry.
sigmaWindowshigh2022-09-27Windows: Unusual Child Process Spawn by dns.exe
Alerts when dns.exe launches an unexpected child process other than conhost.exe.
sigmaWindowshigh2022-09-27Windows dns.exe Deletes Files with Unexpected Targets
Alerts when dns.exe deletes any file other than dns.log on Windows.
sigmaWindowshigh2022-09-27Windows: Unusual File Modification by dns.exe
Alert on dns.exe changing files other than dns.log, which can indicate suspicious or compromised system activity.
sigmaWindowshigh2022-09-27Windows Remote Thread Creation via rundll32 Triggered by wab*, wabmig, or ImagingDevices
Alerts on remote thread creation targeting rundll32.exe from wab* or ImagingDevices.exe process images on Windows.
sigmahigh2022-09-27Windows: w32tm.exe Timer/Delay Usage via stripchart Parameters
Flags w32tm.exe executions using stripchart delay-related parameters that can support timed automation on Windows.
sigmaWindowshigh2022-09-25Windows Process Creation: Renamed createdump.exe Used for .dmp Memory Dumps
Flags renamed createdump.exe executions on Windows that use full dump flags and produce .dmp files.
sigmaWindowshigh2022-09-20Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
sigmaWindowshigh2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
sigmaWindowshigh2022-09-20Windows: Detects NetSupport RAT client32.exe execution using Imphash and filename metadata
Flags renamed NetSupport RAT client32.exe launches on Windows using a specific Imphash and file metadata, while filtering a matching image path.
sigmaWindowshigh2022-09-19Windows: Detect winPEAS privilege escalation reconnaissance execution
Flags Windows executions of winPEAS/PEASS-ng based on image name and command-line discovery options and release download indicators.
sigmaWindowshigh2022-09-19Windows Registry: Tampering ChannelAccess Permissions for WINEVT Event Channels
Alerts on registry updates to WINEVT ChannelAccess that set SDDL permissions granting elevated access to event channels.
sigmaWindowshigh2022-09-17Windows Security 4663: Access to Microsoft Teams token and local storage files
Identifies non-Teams.exe processes accessing Microsoft Teams cookies or local storage objects on Windows (Event 4663).
sigmaWindowshigh2022-09-16